Deployment Architecture

Splunk 5 Clustering: Indexes not seen In clustering dashboard on the master node

dshakespeare_sp
Splunk Employee
Splunk Employee

When looking at the clustering dashboard on the master node, only see the default indexes are listed in the index details: (summary, _audit and _internal). Customer created indexes are not visible.

1 Solution

dshakespeare_sp
Splunk Employee
Splunk Employee

The problem was caused by the fact that repfactor attribute was not set to "auto" for the newly added indexes in the peers indexes.conf.

repFactor=auto is set automatically for the default indexes when you enable clustering, but new indexes that you wish to replicate have to be configured manually.

See http://docs.splunk.com/Documentation/Splunk/5.0/Indexer/Configurethepeerindexes for full information

View solution in original post

VSIRIS
Path Finder

That was the exact setting that I missed, after that rep_factor setting now I see all indexes.

0 Karma

davidpaper
Contributor

Also - customer created indexes don't show up in the clustering dashboard until there is an event in them! This confounded me for hours one day until I decided to send some data to the index, and lo and behold, as soon as there was a hot bucket for the index on one of my indexers, it immediately shows up in the clustering dashboard.

Lucas_K
Motivator

Probably just to do with how the dashboard searches are created. The only way around it is to have a savedsearch csv populating lookup which is then called in the dashboard. This way you can show empty indexes.

0 Karma

dshakespeare_sp
Splunk Employee
Splunk Employee

The problem was caused by the fact that repfactor attribute was not set to "auto" for the newly added indexes in the peers indexes.conf.

repFactor=auto is set automatically for the default indexes when you enable clustering, but new indexes that you wish to replicate have to be configured manually.

See http://docs.splunk.com/Documentation/Splunk/5.0/Indexer/Configurethepeerindexes for full information

Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...